What problem did it solve?
Payroll mistakes cost Malaysian SMEs penalties and staff trust, and most small-business tools only approximate the dense EPF, SOCSO, EIS, PCB and HRD Corp rules.
What was built?
- Engine first, screens second: the statutory engine was verified to the sen against published KWSP, PERKESO and LHDN figures before any payroll UI existed.
- The full Malaysian rule set: EPF Jadual Ketiga, SOCSO categories 1 and 2 with the 2026 rate change, EIS, the real PCB formula, HRD Corp levy, overtime and proration.
- Documents people actually file: BM and English payslips, Borang A, 8A, CP39, EA and E, and leave per the Employment Act 1955 with per-state holidays.
How is it engineered?
Measured from the source repository, not estimated. As of Oct 2026.
Architecture
I built it as a local-first Electron app with a sandboxed, context-isolated React renderer, a main process owning all data, and pure calculation engines for payroll, leave, proration and overtime that run without Electron.
Data and isolation
SQLite with 60 versioned migrations, all money as integer cents, rows scoped per company, and statutory rates held as dated data rows rather than code so a new rate table is data entry.
Security and privacy
- Employee identifiers (NRIC, passport, bank account, EPF, SOCSO, EIS, tax number) and payslip snapshots encrypted per field with AES-256-GCM under a keychain-wrapped data key
- NRIC lookup uses a keyed HMAC, so exact-match search works without decrypting the column
- Four roles (owner, HR, approver, auditor) enforced at one choke point, with auditor writes hard-blocked at the SQLite layer and confidential records hidden from HR by default
- Bilingual PDPA 2010 notice in the add-employee flow; Ed25519 offline licence verification
Regulatory rules in code
It computes EPF (Third Schedule), SOCSO including the 2026 SKBBK rate, EIS, PCB by LHDN's computerised method, HRD Corp levy and Employment Act overtime, and produces CP39, CP22, CP21, CP58, Borang E and EA forms.
Quality evidence
| Unit tests | 191 of 191 pass | Node test runner over the test suite, run on 2026-10-08 |
|---|---|---|
| Statutory golden tests | 34 test cases, table-driven to the sen | Each case cites the official KWSP, PERKESO, EIS, LHDN PCB or HRD Corp schedule |
| End-to-end smoke harnesses | 55 harnesses, 2,318 assertion call sites | Headless Electron runs against a real database, one per milestone |
| Schema migrations | 60 | Distinct versions in the migration registry |
| Commits | 139 (21 Jul 2026 to 7 Oct 2026) | Git history |
Operations
macOS builds are Developer ID signed and Windows installers are built in CI, with an in-app update check that downloads the new installer, folder backups with a manifest and schema check, and an automatic safety copy before any restore.
What was my role?
Product owner, designer, architect and builder. I scoped it, designed it and built it as part of Orbit Suite.
What else shaped the build?
- Part of a suite. Payroll journals export straight into Orbit Finance.
- Overtime, proration and bonuses. Overtime multipliers, proration modes and bonus runs follow the same verified engine.
Where does it stand now?
Orbit HR was first released publicly as v0.4.0 on 7 August 2026 and is now at v0.5.0. It ships as a notarized universal macOS app and a Windows installer, with a 30-day trial and a live sales zone at orbitsuite.io/hr. Milestones M0 to M29 are complete.


